Vulnerability & Security Monitoring
Know about vulnerabilities before attackers do.
New vulnerabilities are disclosed every day, and the software behind your website changes constantly — plugin updates, new endpoints, a config that got left exposed. A scan you ran at launch tells you nothing about what's true today. Continuous vulnerability monitoring checks your site on a schedule and alerts you the moment a new exposure appears.
Why vulnerabilities go unnoticed until it's too late
Attackers don't scan targets once — they scan continuously, using automated tools that check thousands of sites a day against every newly disclosed vulnerability. Most organizations do the opposite: a single security review before launch, then nothing, until something goes wrong. In between, a plugin gets updated and introduces a new flaw, a backup file gets left in a public directory, or a security header quietly disappears during a deploy.
Each of those changes is small and easy to miss by hand. None of them announce
themselves — a misconfigured header doesn't throw an error, and an exposed
.env file loads exactly like any other page. The only way to catch them
reliably is to check for them on the same schedule an attacker would: continuously,
not once.
Continuous vulnerability monitoring closes that gap. Instead of relying on a point-in-time audit or waiting for an incident to reveal the problem, NetTests re-checks your site against known vulnerability signatures, common misconfigurations, and security-header best practices on every run — so a new exposure gets caught within hours, not discovered months later during a breach investigation.
What NetTests vulnerability monitoring checks
NetTests runs a combination of scan types against your site on every scheduled check. A signature-based scan checks your stack against a large, actively maintained detection library covering known Common Vulnerabilities and Exposures (CVEs), exposed admin panels, and default credentials. A path and misconfiguration scan probes for known-bad paths and vulnerable software fingerprints — the same checks a web-server vulnerability scanner would run manually, but repeated automatically on a schedule.
Alongside that, an exposure scan checks for the kind of accidental exposure that doesn't show up in a vulnerability database at all: config files, backup dumps, and admin interfaces that were never meant to be public. And on every check, NetTests grades your HTTP security headers — Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, Referrer-Policy, and Permissions-Policy — and flags when a header that used to be present quietly disappears after a deploy.
Findings are ranked by severity so the most urgent issue is always the one you see first. When something new appears — a finding that wasn't there on the previous check — NetTests flags it as a change, not just another line in a long report, so a fresh exposure never gets buried in noise from issues you've already triaged.
Alerts reach your team through email, Slack, Microsoft Teams, or SMS. The dashboard keeps a full history of every check, so you can see exactly when a finding first appeared and confirm when a fix actually resolved it.
Key features
CVE & signature detection
Checked against a large, actively maintained detection library covering known CVEs, exposed panels, and default credentials.
Known-bad path scanning
Flags vulnerable software fingerprints and common misconfigurations across your web server.
Exposed file & panel detection
Catches exposed config files, backup dumps, and admin panels before attackers find them.
Security header grading
Grades CSP, HSTS, X-Frame-Options, Referrer-Policy, and Permissions-Policy on every check.
Severity-ranked findings
Every finding ranked by severity, so the most urgent issue is always the first thing you see.
New-finding alerts
Flags newly appeared exposures separately from ones you've already triaged, so nothing new gets buried.
Full scan history
Every check logged with timestamps — see exactly when a finding first appeared and confirm when a fix resolved it.
Multi-channel alerts
Reach your team through email, Slack, Microsoft Teams, or SMS the moment a new issue is found.
What you'll see
A live look at findings ranked by severity, with the alert that fires when a new one appears.
Not ready to commit?
Try the free Site Exposure Scanner first. Probe your site for exposed config files, backup dumps, admin panels, and missing security headers — the same checks attackers run — then set up continuous monitoring when you're ready.
Try the free tool →Free vulnerability diagnostic tools
Run a one-off scan now, or set up continuous monitoring.
Scan a web server for known-bad paths, vulnerable software fingerprints, and common misconfigurations.
Grade your CSP, HSTS, X-Frame-Options, Referrer-Policy, and Permissions-Policy headers.
Probe for exposed config files, backup dumps, admin panels, and missing security headers.
Polite TCP-connect port scan of a single public host with optional banner grab.
Frequently asked questions
What's the difference between a one-time scan and continuous vulnerability monitoring?
A one-time scan is a snapshot — it tells you what was true the moment you ran it. New vulnerabilities are disclosed daily, and your own site changes constantly (plugin updates, new deploys, config changes), so that snapshot goes stale quickly. Continuous monitoring re-runs the same checks on a schedule and alerts you the moment something new appears, instead of leaving you to remember to check again.
What is a CVE and why does it matter for monitoring?
A Common Vulnerabilities and Exposures (CVE) is a publicly disclosed, uniquely identified security flaw in a specific piece of software. New CVEs are published constantly against widely used software, libraries, and plugins. If your stack includes a component with a newly disclosed CVE, you're exposed the moment it's published — monitoring checks your site against current CVE data on every run, rather than only at the time you last audited it.
Do you scan for OWASP Top 10 vulnerabilities like SQL injection and XSS?
Yes. Dynamic application scanning crawls your site and probes for the OWASP Top 10 — cross-site scripting (XSS), SQL injection, file inclusion, XXE, and other common web application vulnerabilities — in addition to signature-based CVE detection and misconfiguration checks.
Will scanning my own site cause problems, like triggering my host's abuse alerts?
NetTests scans are scoped to sites you own or administer, and run at a measured pace designed for legitimate ongoing monitoring rather than a burst crawl. That said, if your host or a upstream WAF alerts on any automated traffic, let your provider know you run scheduled security scans against your own domain.
How often are new vulnerability signatures added?
The detection library NetTests scans against is actively maintained and updated as new CVEs, exposed-panel signatures, and default-credential checks are published — you don't need to update anything yourself for a scheduled check to reflect the latest signatures.
Does vulnerability monitoring replace a professional penetration test?
No. Automated monitoring is excellent at continuously catching known vulnerabilities, missing headers, and accidental exposures between audits — the kind of drift that happens silently over months. It doesn't replace a manual penetration test, which can find business-logic flaws and novel attack chains that no automated scanner will detect. Most organizations use both: continuous monitoring day-to-day, and a periodic manual pentest for deeper assurance.
Stop waiting for the next incident to find out
NetTests scans continuously for known vulnerabilities, exposed files, and misconfigurations — so you find out before attackers do.
Start monitoring free →